Public exploit · Metasploit Module

VisiWave VWR File Parsing Vulnerability

Published Rocco Calvi

Exploit summary

A vulnerability in VisiWave Site Survey Report where VisiWaveReport.exe attempts to match a valid pointer based on the ‘Type’ property but fails to properly validate when no match is found, returning the input as a pointer for later use in a CALL instruction. This enables arbitrary code execution and bypasses ASLR and DEP protections.

Source & references